Customer risk assessment (CRA) is the control that sizes every other control in your AML program. It decides how much due diligence a customer needs, how closely you monitor them, and when you review them again.
Get it right, and your resources focus where the real risk is.
Get it wrong or let it fall out of date –> every downstream control is miscalibrated.
This guide explains what customer risk assessment is, the factors and methodology behind it, the shift from static to dynamic scoring, and how to build or buy a model that stays current as your customers change.
What is customer risk assessment?
Customer risk assessment is an anti-money laundering (AML) process that evaluates how much money laundering, terrorist financing, fraud, or sanctions risk a customer brings to your business. It calculates a risk level to determine the required depth of customer due diligence (CDD), transaction monitoring thresholds, and review cadence.
Customer risk assessment is right at the center of the risk-based approach to AML: rather than treating every customer the same, you calibrate due diligence and monitoring to the risk each one actually presents.
You will hear the same idea under several names. In practice, they describe the same function with slightly different emphasis:
Customer risk assessment vs. customer risk rating vs. customer risk scoring
- Customer risk assessment is the overall evaluation process, from gathering data to assigning a risk level.
- Customer risk rating (CRR) usually refers to the output: **the tier a customer lands in, such as low, medium, or high.
- Customer risk scoring refers to the scoring mechanism: the weighted model that turns risk factors into a number, which then maps to a rating.
Throughout this guide, we use customer risk assessment for the overall process, and scoring and rating for those specific steps.
How customer risk assessment works: from data to risk score
At a high level, every customer risk assessment follows the same pipeline, whether it runs in a manual spreadsheet (which it shouldn't, and you'll see why) or on an automated platform:
- Ingest customer data: collect onboarding and KYC attributes, including identity, legal form, occupation or industry, ownership, and expected activity.
- Screen against lists: conduct checks against sanctions, politically exposed person (PEP), and adverse-media lists to surface screening flags.
- Aggregate behavior: collect transaction and activity data over the course of the relationship (volumes, counterparties, geographies, and operational patterns).
- Apply the model: combine risk factors, weights, and rules to calculate a customer risk score.
- Assign a risk level: map the numerical score to a defined tier (from low to high risk).
- Act on the rating: set the intensity of due diligence, transaction monitoring thresholds, and review cadences based on the assigned tier.
The quality of the assessment depends on every stage: clean data in, accurate lists, a model that reflects your real exposure, and a reliable mechanism to keep the result current as those inputs change.
Why customer risk assessment matters
Customer risk assessment is the control that sizes every other control.
The risk level you assign determines how much customer due diligence (CDD) a customer receives, whether enhanced due diligence (EDD) applies to a high-risk customer, how tightly transactions are monitored, and how often the relationship is reviewed.
If the assessment is inaccurate or out of date, everything downstream is miscalibrated: you over-scrutinize low-risk customers and under-watch the riskier ones.
The regulatory foundation
The risk-based approach is not optional.
The FATF sets it as the global standard in its Recommendation 1, requiring institutions to identify, assess, and understand their money laundering and terrorist financing risks, and to apply resources accordingly.
In the United States, the Bank Secrecy Act and the FFIEC BSA/AML Examination Manual require risk-based AML programs and customer due diligence.
In the EU, the AML framework (including the new AML Regulation (AMLR) and the EU's AML Authority (AMLA)) reinforces differentiated, risk-based obligations.
Across regimes, regulators expect you to justify why a customer is assigned a given risk level and to document your underlying methodology.
The business case
Beyond compliance, a sound customer risk assessment makes your whole operation more efficient.
Focus EDD where the risk actually is, and analysts stop drowning in low-value reviews. Calibrate monitoring thresholds to risk, and you cut false positives without missing genuine threats.
A clear, defensible methodology also shortens audits and regulatory exams because the rationale for every rating is already documented.
Core AML risk factors to assess
Most frameworks group risk factors into a handful of categories, closely following FATF guidance. The goal is not to model everything, but to select the factors that most reliably separate higher-risk customers from lower-risk ones in your book.
Customer and entity factors
Who the customer is: whether they are an individual or a legal entity, their occupation or business activity, ownership and control, PEP status, and any adverse media. Complex or opaque ownership structures typically raise risk.
Geographic risk
Where the customer is based or connected: residence, nationality, place of incorporation, and the countries they transact with. Naturally, high-risk jurisdictions – for sanctions, corruption, or weak AML controls – raise the rating.
Product, service, and channel risk
What the customer uses and how they access it: cash-intensive products, private banking, correspondent relationships, or anonymous and non-face-to-face channels all carry more inherent risk.
Transaction and behavioral risk
How the customer actually transacts: volumes, frequency, cross-border activity, and counterparties. Behavior is the most revealing factor because it reflects reality rather than expectation and because it changes over time.
How to build a customer risk assessment model, step by step
- Define your risk levels: decide how many tiers you will use – typically three to six, from low to high. Fewer tiers are simpler to operate. More tiers give finer control over review frequency and EDD triggers. Align the choice with your own risk framework.
- Select and weight your risk factors: choose the key AML risk factors from the categories above that matter most for your customer base. Assign each a weight reflecting its importance. Start with the five to ten highest-signal factors.
- Score customers and set thresholds: turn factors and weights into a customer risk score, then set the thresholds that map scores to risk levels. Ensure certain critical factors carry a minimum floor (for example, an active sanctions match should automatically push an account to a high-risk customer tier regardless of total score).
- Map ratings to due diligence: connect each risk level to concrete operational actions (for example, standard CDD for low risk, enhanced due diligence and closer monitoring for high risk, and a defined review frequency for each tier).
- Validate, document, and review: backtest the model against a sample of your customer base to verify distribution logic. Document your methodology for auditors. Establish a scheduled cadence to revisit weights and thresholds as risk exposure evolves.
Static vs. dynamic customer risk assessment
The limits of point-in-time assessment
Traditionally, customer risk assessment happens at onboarding and then at fixed intervals (annually, or every few years for lower-risk customers).
The problem with this is simple: customer risk does not wait for the review date.
A new sanctions listing, a change in ownership, a shift in transaction behavior, or a move into a high-risk corridor can change a customer's risk overnight. A score set once and revisited yearly is out of date the moment the underlying data changes.
Event-driven and continuous reassessment (a.k.a perpetual KYC)
Modern programs are shifting to dynamic, event-driven customer risk assessment – often called perpetual KYC. Instead of waiting for a scheduled review, the risk level recomputes whenever something material changes: a fresh screening hit, a profile update, a new pattern of transactions, or simply the passage of a set interval.
This keeps ratings current, surfaces rising risk earlier, and reduces the manual burden of periodic re-scoring. It also depends on the assessment living close to the data that feeds it – screening and transaction monitoring in particular.
Build vs. buy: choosing a customer risk assessment solution
Manual and spreadsheet-based approaches (and where they break)
Many teams start with a spreadsheet model.
It is flexible and cheap. But it does not scale: scores go stale between manual refreshes, there is no live link to screening or transaction data, version control is fragile, and proving the methodology to an auditor becomes a project in itself.
As customer volumes grow, manual assessment becomes both a bottleneck and a risk in its own right.
What to look for in a CRA solution
If you evaluate a customer risk assessment or customer risk rating solution, weigh it against a few essentials:
- Your methodology – not the vendor's: you should own the factors, weights, and thresholds, and adjust them anytime.
- Explainable and auditable: every rating should trace back to the exact rules that produced it, with no black box.
- Integrated with screening and monitoring: the score should draw on screening flags and transaction behavior directly, not through manual exports and imports.
- Automated and always current: scores should recompute on relevant events and on a set cadence, so no rating drifts out of date.
- Backtesting and versioning: test changes on historical data before they go live, and keep an immutable history of your methodology.
- Deployment and data residency: SaaS, on-premise, or self-hosted options with clear data handling that fit your legal obligations.
Best practices and common pitfalls
A few principles separate strong customer risk assessments from fragile ones:
- Don't over-rely on a single factor: risk is multi-dimensional, and one input rarely tells the whole story.
- Don't let scores go stale: a rating is only useful if it reflects the customer today.
- Avoid black-box models: if you cannot explain a rating to an auditor, you cannot defend it.
- Use behavioral signals, not just static attributes: how a customer transacts is often more telling than who they declared themselves to be at onboarding.
- Document everything: keep detailed logs of your methodology, your weights, and your updates so audits are routine rather than fire drills.
How Marble approaches customer risk assessment
Marble builds customer risk assessment, its customer risk scoring engine, around the dynamic model outlined above.
You define the methodology: rules aligned to standard risk-factor categories, your own thresholds, and your company's risk appetite.

Marble then scores every customer automatically and keeps each rating current, recomputing when a customer is onboarded, when their profile changes, when screening status moves, or on the review cadence you set. Even quiet accounts never drift out of date.

Because scoring sits on the same platform as AML screening, continuous screening, and transaction monitoring, screening flags feed the score directly, and risk levels flow back into monitoring thresholds – stricter for a high-risk customer, lighter for low-risk – and into AI-assisted case review.
Every ruleset is versioned and backtestable, and because scoring factors in confirmed-risk outcomes from past cases, it sharpens over time. When an auditor asks how a customer reached a given level, the answer is already in the system.
See customer risk assessment on your data
Ready to move from static spreadsheets to scoring that stays current on its own?
- Book time with our experts: Talk to Marble
- Prefer to read first? Download the one-pager
- Want the hands-on detail? Explore the documentation
Frequently asked questions
What is a customer risk assessment in AML?
A customer risk assessment is the process of evaluating the money laundering, terrorist financing, fraud, and sanctions risk a customer poses, then assigning a risk level that determines how much due diligence and monitoring they receive. It is the foundation of the risk-based approach required by AML regulators worldwide.
What are the main customer risk factors?
Most frameworks assess four core categories: customer and entity factors (such as PEP status, occupation, and ownership), geographic risk, product/service/channel risk, and transaction or behavioral risk. Institutions select and weight the factors most relevant to their customer base.
What is the difference between customer risk rating and customer risk scoring?
Customer risk scoring is the mechanism – the weighted model that turns risk factors into a number. Customer risk rating is the output – the tier that score maps to, such as low, medium, or high. Both are steps within the broader customer risk assessment process.
How often should customer risk assessments be updated?
Under a static model, assessments are updated at onboarding and at set intervals based on risk tier. Increasingly, institutions use dynamic or perpetual KYC, where the assessment recomputes whenever a material change occurs – a screening hit, a profile update, or a shift in transaction behavior – rather than waiting for a scheduled periodic review.
Is customer risk assessment a regulatory requirement?
Yes. The risk-based approach, which depends on customer risk assessment, is mandated by global FATF standards and national regimes, including the US Bank Secrecy Act and the EU AML framework. Regulators expect a documented, defensible, and up-to-date methodology.

